Viktor Dukhovni d02d80b2e8 Limit scope of CN name constraints
Don't apply DNS name constraints to the subject CN when there's a
least one DNS-ID subjectAlternativeName.

Don't apply DNS name constraints to subject CN's that are sufficiently
unlike DNS names.  Checked name must have at least two labels, with
all labels non-empty, no trailing '.' and all hyphens must be
internal in each label.  In addition to the usual LDH characters,
we also allow "_", since some sites use these for hostnames despite
all the standards.

Reviewed-by: Matt Caswell <matt@openssl.org>
Reviewed-by: Tim Hudson <tjh@openssl.org>
2018-05-23 11:12:13 -04:00
..
2016-06-20 21:34:37 +02:00
2016-06-20 21:34:37 +02:00
2016-06-20 21:34:37 +02:00
2015-07-07 21:57:11 +01:00
2015-07-07 21:57:11 +01:00
2017-03-14 15:18:07 -04:00
2017-02-16 16:43:44 +00:00
2017-05-30 20:38:20 +01:00
2016-03-01 20:03:25 +00:00
2016-03-01 20:03:25 +00:00
2015-07-07 21:57:11 +01:00
2015-07-07 21:57:11 +01:00
2015-07-07 21:57:11 +01:00
2015-07-07 21:57:11 +01:00
2018-03-20 13:08:46 +00:00
2016-06-08 11:37:06 -04:00
2016-06-20 21:34:37 +02:00
2016-06-20 21:34:37 +02:00
2016-06-20 21:34:37 +02:00
2016-06-20 21:34:37 +02:00
2016-06-20 21:34:37 +02:00
2016-06-20 21:34:37 +02:00
2017-05-30 20:38:20 +01:00
2015-07-07 21:57:11 +01:00
2015-07-07 21:57:11 +01:00
2015-07-07 21:57:11 +01:00
2018-05-23 11:12:13 -04:00
2015-07-07 21:57:11 +01:00
2015-07-07 21:57:11 +01:00
2015-07-07 21:57:11 +01:00
2015-07-07 21:57:11 +01:00